|
303031
|
- |
|
hp
|
openvms openvms_for_integrity_servers
|
Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive informatio…
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2010-2612
|
2024-11-21 10:17 |
2010-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303032
|
5.5 |
MEDIUM
Local
|
clusterlabs
|
cluster_glue pacemaker
|
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its o…
|
CWE-287
Improper Authentication
|
CVE-2010-2496
|
2024-11-21 10:16 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303033
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An unprivileged local attacker could exploit this flaw to gain access or execute any file stored in the gfs2 file …
|
-
|
CVE-2010-2525
|
2024-11-21 10:16 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303034
|
7.5 |
HIGH
Network
|
znc
|
znc
|
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-2488
|
2024-11-21 10:16 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303035
|
9.8 |
CRITICAL
Network
|
syscp_project
|
syscp
|
syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.
|
CWE-20
Improper Input Validation
|
CVE-2010-2476
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303036
|
7.5 |
HIGH
Network
|
shibboleth debian
|
service_provider debian_linux
|
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default…
|
CWE-200 CWE-916
Information Exposure Use of Password Hash With Insufficient Computational Effort
|
CVE-2010-2450
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303037
|
6.5 |
MEDIUM
Network
|
gource
|
gource
|
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
|
CWE-20
Improper Input Validation
|
CVE-2010-2449
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303038
|
9.8 |
CRITICAL
Network
|
gitolite
|
gitolite
|
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
|
CWE-20
Improper Input Validation
|
CVE-2010-2447
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303039
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal s…
|
CWE-20
Improper Input Validation
|
CVE-2010-2473
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303040
|
4.8 |
MEDIUM
Network
|
drupal
|
drupal
|
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which c…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2472
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|